Privacy
Last updated: 15 September 2026
Before this page goes liveA lawyer should read this. It describes the system accurately, but accuracy is not the same as legal sufficiency — and the company details in the Imprint have to be filled in first.
Vektra is an assistant that answers questions on a customer's website using text taken from that website. This page explains what we do with data, in plain terms. There are two different groups of people involved, and the rules are different for each.
Who is responsible for what
For our customers — the businesses who buy Vektra — we are the controller of their account data.
For the visitors of our customers' websites, we are a processor. The shop owner decides that the assistant runs on their pages; we act on their instructions. Before a customer goes live we sign an Article 28 data processing agreement with them.
If you are a customer
| What we store | Your email address, your company name, a password hash (never the password), the websites you added, and the keys issued for them. |
|---|---|
| Why | To run your account. Without it there is no login and no assistant. |
| How long | While your account exists. Delete the account and it goes. |
| Passwords | Stored as a scrypt hash with a salt unique to your account. We cannot read your password, and neither can anyone who takes a copy of the file. |
| Google sign-in | If you use it, we receive your email address and nothing else. We do not keep the access token. |
If you are a visitor on a customer's website
When you ask the assistant something, the question is sent to our server, matched against text from that website, and passed to a language model to be answered.
| The question | Sent to the language model together with passages from the website. Not stored as a conversation log. |
|---|---|
| Your email address | Only if you type it in yourself, after the assistant could not answer. It is stored for the shop owner, who then replies to you. |
| Helpful / not helpful | Stored with the question and answer, so the shop owner can see what the assistant gets wrong. |
| The page you were on | Stored with your email address, so the shop owner knows what you were looking at. Only the address of the page, nothing from it. |
| Cookies | The assistant sets none. There is no tracking, no profile, and no advertising identifier. |
Who else sees the data
The question and the matched passages are sent to a language model provider to produce the answer. Today that is OpenAI. The provider does not use this data to train models. No account data, no email addresses and no lead data are sent to them — only the question and the passages needed to answer it.
The application and its data run on infrastructure inside the EU.
Reading a customer's website
Our crawler fetches the public pages of a customer's website and stores their text so the assistant can answer from it. It identifies itself in the server log, respects the parts of a site marked as excluded, and reads nothing that is behind a login.
What we count
We count how many conversations and questions each website has each month, because that is what the price plans are based on. The counter holds numbers only — no questions, no addresses.
Your rights
You can ask for a copy of your data, ask for it to be corrected, or ask for it to be deleted. If you are a visitor on a shop that uses Vektra, send that request to the shop — they decide, and we act on it. Write to us at hello@nexuscode.hu either way and we will route it.
Changes
If we change what we do with data, this page changes with it, and the date at the top moves.